Last updated: July 6, 2026
1. Scope & roles
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Sapilon ("Sapilon", the "Processor") and the customer (the "Controller"). It applies whenever Sapilon processes personal data on the Controller's behalf in the course of providing the platform, chiefly personal data contained in the Controller's project content. It implements Article 28 of the GDPR.
For account, billing, and website data, Sapilon is itself the controller; that processing is described in the Privacy Policy, not this DPA.
2. Details of processing
- Subject matter: provision of the Sapilon platform: building, modernizing, governing, and operating the Controller's software projects.
- Duration: the term of the Terms of Service, plus the export window in section 9.
- Nature & purpose: hosting, storage, AI-assisted transformation and generation of code and content, execution in Build, Rehearsal, and Live Server environments, audit logging, and backup.
- Categories of data subjects: the Controller's personnel and end users, and any individuals whose data the Controller includes in project content.
- Categories of personal data: determined by the Controller. Typically contact and account identifiers, business records, and any personal data present in migrated legacy systems. The platform is not designed for special-category data; the Controller must not submit it without a separate written agreement.
3. Processor obligations
Sapilon will:
- process personal data only on the Controller's documented instructions (given through the platform, the Terms, and this DPA) unless EU or member-state law requires otherwise, in which case we inform the Controller before processing unless that law forbids it;
- ensure persons authorized to process the data are bound by confidentiality;
- inform the Controller immediately if, in our opinion, an instruction infringes the GDPR;
- not use personal data in project content to train AI models, and contractually require the same of the AI sub-processor;
- make available the information necessary to demonstrate compliance with Article 28.
4. Security measures (Art. 32)
Taking into account the state of the art and the risks of the processing, Sapilon implements:
- Encryption in transit (TLS) and at rest for platform data stores and backups.
- Environment isolation: customer projects run in separated Build, Rehearsal, and Live Server environments; production data does not flow back into build environments.
- Governed AI access: AI agents operate inside explicit ownership zones, with automated review on generated changes; every AI action is logged, diffable, and reversible.
- Access control: role-based access, least privilege for operational access to customer data, and audit trails on administrative actions.
- Backups and tested restore procedures for platform-hosted data.
- Secrets management: credentials and API keys are stored in managed secret stores, never in code.
Current practices are described on the Trust & Security page. We may improve measures over time provided the overall level of protection does not decrease.
5. Sub-processors
The Controller gives general authorization for the sub-processors below. Sapilon imposes data-protection obligations on each that are no less protective than this DPA, and remains fully liable to the Controller for their performance.
| Sub-processor | Purpose | Location & safeguards |
|---|---|---|
| Amazon Web Services (AWS) | Hosting of the platform, project data, and customer environments | EU (default regions) |
| Anthropic | AI model processing (Claude) of prompts and project content | US / EU, under SCCs; no training on customer content |
| Stripe | Payment processing for wallet top-ups | EU / US, under SCCs |
| Google (Analytics) | Consent-gated website analytics (sapilon.com only, not platform data) | EU / US, under SCCs |
We will give at least 30 days' notice before adding or replacing a sub-processor, by email to account holders and by updating this page. If the Controller has a reasonable data-protection objection and no workaround exists, the Controller may terminate the affected services and receive a pro-rata refund of unused paid wallet balance.
6. Data location & transfers
Platform data and customer environments are hosted in AWS regions in the European Union by default. Where the Controller deploys to its own AWS account, the Controller chooses the region. Transfers of personal data outside the EU/EEA (for example, to Anthropic or Stripe infrastructure in the United States) take place only under the European Commission's Standard Contractual Clauses, an adequacy decision, or another valid transfer mechanism under Chapter V of the GDPR.
7. Assistance to the Controller
Taking into account the nature of the processing, Sapilon assists the Controller with appropriate technical and organizational measures to respond to data-subject requests (access, rectification, erasure, portability, restriction, objection), and assists with the Controller's obligations under Articles 32–36 (security, breach notification, data-protection impact assessments, prior consultation). Requests from the Controller's data subjects that reach us directly are forwarded to the Controller without undue delay.
8. Breach notification
Sapilon notifies the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data, and in any case within 48 hours, providing the information reasonably available: nature of the breach, categories and approximate volumes affected, likely consequences, and measures taken or proposed. We document breaches and cooperate with the Controller's notifications to authorities and data subjects.
9. Return & deletion
Project content lives in plain Git repositories the Controller can export at any time; software deployed to the Controller's own AWS account is already in the Controller's possession. On termination, Sapilon keeps platform-hosted project data available for export for at least 30 days, then deletes it, including from backups within the backup rotation period, unless EU or member-state law requires longer storage. On request we confirm deletion in writing.
10. Audits
Sapilon makes available the information necessary to demonstrate compliance with this DPA: documentation, the Trust & Security page, and, as they are achieved, third-party certifications and audit reports. Where these are insufficient, the Controller may conduct an audit (at most once per year, on 30 days' notice, during business hours, without disrupting other customers' data or operations), itself or through an independent auditor bound by confidentiality. Each party bears its own audit costs.
11. Liability & precedence
Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms on a data-protection matter, this DPA prevails. Invalidity of a provision does not affect the rest; the parties will replace it with a valid provision closest to its intent.
12. How this DPA applies
During early access, this DPA applies automatically to every customer as part of the Terms of Service; no signature needed. If your organization requires a countersigned copy or has specific requirements (regions, additional safeguards, an enterprise DPA), email we@sapilon.com and we will arrange it.